Impact
Based on the description, the flaw resides in the high‑level diff API of GitPython 3.1.59, where the --no-index switch is not properly constrained. An attacker can invoke GitPython with this option to feed arbitrary file system paths as repository operands. By pairing --no-index with the -I/--ignore-matching-lines flag, the attacker turns the API into a content‑dependent Boolean oracle, repeatedly probing local files and distinguishing success from error responses. This indicates that the attacker must be able to execute the GitPython code locally on the target host. Using this capability, the attacker can recover single‑line secrets such as passwords, API keys, or other sensitive data found in the filesystem, presenting a clear confidentiality risk.
Affected Systems
Vendors: GitPython developers. Product: GitPython 3.1.59. The vulnerability is specific to this release and does not affect earlier or later versions that have applied the patch and removed the unchecked usage of --no-index.
Risk and Exploitability
Based on the description, the likely attack vector involves local execution of the vulnerable GitPython code on the target host. This local execution is needed to supply arbitrary filesystem paths via --no-index and probe file contents by exploiting the Boolean oracle. The CVSS score of 7.1 indicates high severity, and the lack of an EPSS score and KEV listing suggest no widespread exploitation yet. Attackers able to run the compromised code locally can repeatedly query local files, distinguishing success from error responses, potentially exfiltrating secrets if present on the system. Overall, despite the absence of remote entry, the combination of local execution and unchecked --no-index handling creates a significant confidentiality risk.
OpenCVE Enrichment